Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total16,248
Critical1,013
High3,368
Medium11,615
Reset
Showing 13301-13320 of 16248 records
Threat Entry Updated 2024-11-21

CVE-2023-35090 - Masterstudy Lms Plugin

Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in StylemixThemes MasterStudy LMS WordPress Plugin – for Online Courses and Education plugin

PLUGIN Masterstudy Lms

CVE-2023-35090

MEDIUM CVSS 6.5 2023-06-22
Threat Entry Updated 2024-11-21

CVE-2023-3325 - Cms Commander Plugin

The CMS Commander plugin for WordPress is vulnerable to authorization bypass due to the use of an insufficiently unique cryptographic signature on the 'cmsc_add_site' function in versions up to, and including, 2.287. This makes it possible for unauthenticated attackers to the plugin to change the '_cmsc_public_key' in the plugin config, providing access to the plugin's remote control functionalities, such as creating an admin access URL, which can be used for privilege escalation. This can only be exploited if the plugin has not been configured yet, however, if combined with another…

PLUGIN Cms Commander

CVE-2023-3325

HIGH CVSS 8.1 2023-06-20
Threat Entry Updated 2024-11-21

CVE-2023-3320 - Wp Sticky Social Plugin

The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing nonce validation in the ~/admin/views/admin.php file. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

PLUGIN Wp Sticky Social

CVE-2023-3320

MEDIUM CVSS 6.1 2023-06-20
Threat Entry Updated 2024-12-12

CVE-2023-2719 - Before 3 Plugin

The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the `id` parameter for an Agent in the REST API before using it in an SQL statement, leading to an SQL Injection exploitable by users with a role as low as Subscriber.

PLUGIN Before 3

CVE-2023-2719

HIGH CVSS 8.8 2023-06-19
Threat Entry Updated 2024-12-12

CVE-2023-2359 - Slider Revolution Plugin

The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.

PLUGIN Slider Revolution

CVE-2023-2359

HIGH CVSS 8.8 2023-06-19
Threat Entry Updated 2024-11-21

CVE-2023-2805 - Before 3 Plugin

The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the agents[] parameter in the set_add_agent_leaves AJAX function before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

PLUGIN Before 3

CVE-2023-2805

HIGH CVSS 7.2 2023-06-19
Threat Entry Updated 2024-12-12

CVE-2023-2492 - Querywall Plug N Play Firewall Plugin

The QueryWall: Plug'n Play Firewall WordPress plugin through 1.1.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.

PLUGIN Querywall Plug N Play Firewall

CVE-2023-2492

HIGH CVSS 7.2 2023-06-19
Threat Entry Updated 2024-12-12

CVE-2023-2779 - Social Login And Social Comments Plugin

The Social Share, Social Login and Social Comments WordPress plugin before 7.13.52 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

PLUGIN Social Login And Social Comments

CVE-2023-2779

MEDIUM CVSS 6.1 2023-06-19
Threat Entry Updated 2024-12-12

CVE-2023-2654 - Conditional Menus Plugin

The Conditional Menus WordPress plugin before 1.2.1 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

PLUGIN Conditional Menus

CVE-2023-2654

MEDIUM CVSS 6.1 2023-06-19
Threat Entry Updated 2024-12-12

CVE-2023-2399 - Before 1 Plugin

The QuBot WordPress plugin before 1.1.6 doesn't filter user input on chat, leading to bad code inserted on it be reflected on the user dashboard.

PLUGIN Before 1

CVE-2023-2399

MEDIUM CVSS 6.1 2023-06-19
Threat Entry Updated 2024-12-12

CVE-2023-2899 - Google Map Shortcode Plugin

The Google Map Shortcode WordPress plugin through 3.1.2 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin

PLUGIN Google Map Shortcode

CVE-2023-2899

MEDIUM CVSS 5.4 2023-06-19
Threat Entry Updated 2024-12-12

CVE-2023-2751 - Upload Resume Plugin

The Upload Resume WordPress plugin through 1.2.0 does not validate the captcha parameter when uploading a resume via the resume_upload_form shortcode, allowing unauthenticated visitors to upload arbitrary media files to the site.

PLUGIN Upload Resume

CVE-2023-2751

MEDIUM CVSS 5.3 2023-06-19
Threat Entry Updated 2024-11-21

CVE-2023-2812 - Ultimate Dashboard Plugin

The Ultimate Dashboard WordPress plugin before 3.7.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN Ultimate Dashboard

CVE-2023-2812

MEDIUM CVSS 4.8 2023-06-19
Threat Entry Updated 2025-05-12

CVE-2023-2811 - Ai Chatbot Plugin

The AI ChatBot WordPress plugin before 4.5.6 does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks to all admin when setting chatbot and all client when using chatbot

PLUGIN Ai Chatbot

CVE-2023-2811

MEDIUM CVSS 4.8 2023-06-19
Threat Entry Updated 2025-05-12

CVE-2023-2742 - Ai Chatbot Plugin

The AI ChatBot WordPress plugin before 4.5.5 does not sanitize and escape its settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

PLUGIN Ai Chatbot

CVE-2023-2742

MEDIUM CVSS 4.8 2023-06-19
Threat Entry Updated 2024-12-11

CVE-2023-2684 - File Renaming On Upload Plugin

The File Renaming on Upload WordPress plugin before 2.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

PLUGIN File Renaming On Upload

CVE-2023-2684

MEDIUM CVSS 4.8 2023-06-19
Scroll to top